This is a broad remote tool gateway that is disclosed, but it can use persistent credentials, invoke account-linked services, fetch untrusted skill content, and affect ratings without clear user confirmation boundaries.
Install only if you trust MCPMarket as a broker for broad tool calls and account authorization. Require confirmation before posts, purchases, deletions, financial or business changes, downstream OAuth linking, downloads, loading fetched skills, or submitting ratings. Remove ~/.uno/token when finished and separately revoke any linked downstream service access in MCPMarket or the connected service.